Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 337

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Fed's Kashkari says 'now is the time to start slowly moving' rates up
Private companies added just 44,000 workers in July, below expectations, ADP reports
Warren presses Lutnick over UAE access to sensitive U.S. tech after Trump crypto investment
Oil prices fall on negotiations to manage ship traffic in Strait of Hormuz
Saudi wealth fund and Jared Kushner's Affinity finalize $55 billion EA Sports deal
Abdul El-Sayed wins Michigan Democratic Senate primary as voters pivot to the left
Another "identify this title from my youth" question
Silo: Memory Show Only
Uber stock sinks 7% after weak guidance despite revenue growth
Stargate SG-1: The Warrior Rewatch